Abbott Laboratories is investigating two cybersecurity incidents after extortion actors claimed access to company-related systems and data. Abbott confirmed unauthorized access to limited internal legacy Exact Sciences systems within its Cancer Diagnostics business after ShinyHunters listed the company on its leak site, while a separate actor, ShadowByt3$, claimed to have breached Abbott's third-party-hosted LabCentral customer portal using compromised customer credentials. Abbott said the Exact Sciences-related incident was limited in scope and did not affect operations, manufacturing, lab operations, patient service, or other Abbott businesses, and it said the LabCentral portal contains only public technical reference materials rather than sensitive customer or business data.
ShinyHunters alleged it carried out a mid-June vishing attack against Abbott employees, compromised a Microsoft Entra SSO account, and exfiltrated data from multiple connected systems, including customer and medical information, before issuing an extortion deadline and threatening to leak the data. Separate reporting identified Exact Sciences, described as Abbott-owned and operating in the U.S. healthcare sector, as the victim named on the ransomware gang's site. Abbott said it is probing both matters, and as of the latest reporting, neither ShinyHunters nor ShadowByt3$ had publicly released the allegedly stolen data.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Abbott said it notified law enforcement, activated incident response procedures, and brought in external cybersecurity experts as it investigated the two cyber incidents affecting its diagnostics-related systems. The company also said the incidents were isolated from core infrastructure and had not disrupted operations.
Abbott confirmed unauthorized access to limited internal legacy Exact Sciences systems within its Cancer Diagnostics business after ShinyHunters listed the company on its leak site. Abbott said the incident was limited in scope and had not affected operations, manufacturing, lab operations, patient service, or other Abbott businesses.
ShinyHunters claimed it used a mid-June vishing attack against Abbott employees to compromise a Microsoft Entra SSO account and exfiltrate data from multiple connected systems, including customer and medical information. BleepingComputer noted these claims were not independently verified.
Abbott disclosed on July 16, 2026 that it was investigating unauthorized access to a limited environment tied to its Cancer Diagnostics business. The company said it was assessing the scope and impact of the incident.
Exact Sciences Corporation was listed by ShinyHunters as the victim of a ransomware-related data breach, with the gang claiming data had been exfiltrated and threatening public leakage if the victim did not make contact by July 18, 2026. The notice was characterized as a final warning.
ShadowByt3$ claimed it accessed Abbott's LabCentral customer portal on July 4, 2026 using compromised customer credentials and stole product-related documents. Abbott said the third-party-hosted portal contains only public technical reference materials and no sensitive customer or business data.
After the July 2026 extortion attempt, ShinyHunters later published data it claimed to have stolen from Exact Sciences' cancer diagnostics business. The exposed dataset reportedly included 10.9 million email addresses plus names, addresses, phone numbers, and health records, and Abbott said some impacted files contained personal information and/or personal health information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
13 references tracked. Mallory keeps watching after this page renders.
haveibeenpwned.com
Open sourcecybersecuritynews.com
Open sourceteiss.co.uk
Open sourcemalware.news
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceabbott.com
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.